MessageQueue resolves inherited Object properties as callable modules

Open Beginner friendly
#58,198 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
70/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
javascript, react-native
Domain
mobile

Research direction

Start at the legacy bridge's MessageQueue registry and the getCallableModule entry point. Check how arbitrary names are looked up and assigned, then verify that unregistered names do not resolve through Object.prototype and that every valid string name, including proto, can be registered and retrieved.

Written by the indexing model from the issue text.

Description

Needs: Author Feedback Needs: Repro
Description

The legacy bridge stores lazy callable-module initializers in an ordinary object and reads it by arbitrary module name. Unregistered names such as constructor and __proto__ therefore resolve through Object.prototype; getCallableModule('constructor') invokes the inherited constructor and returns an object although no module was registered. Assigning __proto__ also changes the registry prototype instead of creating a normal module entry.

Expected behavior

Only explicitly registered callable modules should resolve, and every valid string name—including __proto__—should be registrable.

React Native Version

0.87.1 and current main

Affected Platforms

Runtime - All

Dominant language
C++
Stars
127k
Forks
25.3k
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from react/react-native

All issues in react/react-native

Similar issues

More C++ issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.